Privacy Policy (GDPR)

Last updated: 3 January 2026

This Privacy Policy explains how Mabuhay.gr (the “Platform”) collects, uses, shares, and protects personal data when you use the website. It also explains your rights under the General Data Protection Regulation (GDPR).

Important: We do not use Google Analytics at this time.

1. Who we are (Data Controller)

The data controller is the operator of Mabuhay.gr (“we”, “us”). For privacy questions or requests, contact: info@mabuhay.gr.

2. What personal data we collect

Depending on how you use the Platform, we may collect:

  • Account data: email, phone (if provided), password (stored in encrypted/hashed form), account type.
  • Profile data: service categories, experience, availability, location/area, and other profile fields you choose to submit. Photos and a short bio are optional and provided only if you want to publish them.
  • You may also publish personal information in free-text areas (for example an “About” text) at your own discretion and responsibility. Please avoid sharing sensitive information publicly.

  • Verification data: identity details and documents you upload or send for account approval/verification (as requested).
  • Communication data: messages and interactions within the Platform and support communications by email.
  • Technical data: IP address, device/browser information, and logs necessary for security and performance.
  • Payment/admin data (if applicable): billing details needed to issue a lawful receipt/invoice for website/platform services.

Please do not upload or share sensitive information unless we explicitly request it for verification. You may redact non-essential fields when possible.

3. How profile visibility works (closed community)

The Platform is designed as a closed community. Profiles are not visible to all registered users by default. A profile becomes visible only after a mutual selection: one user expresses interest and the other user accepts it.

Until mutual selection, certain personal details may be shown with partial masking (for example: Sp****os) to reduce unnecessary exposure.

4. Why we process your data (purposes) and legal bases

We process personal data for the following purposes and legal bases:

  • Provide the Platform and account features (contract performance / steps before entering a contract).
  • Enable matching and user-to-user contact (contract performance and/or legitimate interests).
  • Account approval and identity verification to reduce misuse, fraud, and harm (legitimate interests; and compliance where required).
  • Customer support and assistance with platform use (contract performance and/or legitimate interests).
  • Security, abuse prevention, and incident investigation (legitimate interests and legal obligations where applicable).
  • Legal and tax compliance (legal obligation), including issuing receipts/invoices for platform services where applicable.

5. Identity verification

To reduce misuse and to protect the community, we may require identity verification before approving access or when necessary for safety and integrity reasons. Verification can reduce risk but does not guarantee the identity, intentions, or conduct of any user.

6. Data retention

We generally retain personal data for as long as your account remains active and until you delete your data or request deletion. We do not delete your personal data without your request, except where deletion is required or permitted by law, or where action is necessary for security, fraud prevention, abuse handling, or protection of the Platform and users.

Backups may keep residual copies for a limited period. Where possible, data will be removed from active systems promptly after deletion requests, and from backups according to their rotation schedule.

7. Who we share data with

We may share personal data with:

  • Other users when you choose to connect and/or after mutual selection (as described above).
  • Service providers (processors) who help us operate the Platform (hosting, email delivery, security, support tools, payment providers where applicable).
  • Authorities or legal advisors when required to comply with law or to protect rights and safety.

We do not sell personal data.

8. International transfers

Our service providers may be located in the European Economic Area (EEA) or, where necessary, outside the EEA. If data is transferred outside the EEA, we use appropriate safeguards (for example, Standard Contractual Clauses) where applicable.

9. Security

We use reasonable technical and organizational measures to protect personal data (access controls, least-privilege access, and security monitoring). No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.

10. Your GDPR rights

Depending on your situation, you may have the right to:

  • Access your personal data;
  • Correct inaccurate or incomplete data;
  • Request deletion (“right to be forgotten”) where applicable;
  • Restrict processing in certain cases;
  • Data portability in certain cases;
  • Object to processing based on legitimate interests;
  • Withdraw consent where processing is based on consent.

To exercise your rights, contact info@mabuhay.gr.

You also have the right to lodge a complaint with your local data protection authority. In Greece, this is the Hellenic Data Protection Authority (HDPA).

Data Storage Location

User data is stored in a MongoDB Atlas database hosted on Amazon Web Services (AWS) in Frankfurt, Germany (region eu-central-1), within the European Union.

11. Cookies

We use cookies and similar technologies that are necessary for core functionality (for example, login/session and security). We do not use Google Analytics at this time. If we add non-essential cookies in the future, we will update this policy accordingly.

You can control cookies through your browser settings. Disabling essential cookies may prevent parts of the Platform from working properly.

12. Children

The Platform is intended for adults (18+). We do not knowingly collect personal data from children.

13. Changes to this policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated “Last updated” date.

14. Contact

If you have questions about this Privacy Policy or how we process personal data, contact: info@mabuhay.gr.